IP Library Granted Patent US 10,791,099
Granted Patent B2
US 10,791,099 · App. 16/159,437 · Granted Sep 29, 2020

Secure session capability using public-key cryptography without access to the private key

Inventors: Sébastien Andreas Henry Pahl (San Francisco, CA); Matthieu Philippe François Tourne (San Francisco, CA); Piotr Sikora (San Francisco, CA); Ray Raymond Bejjani (San Francisco, CA); Dane Orion Knecht (San Francisco, CA); Matthew Browning Prince (San Francisco, CA); John Graham-Cumming (London, GB); Lee Hahn Holloway (Santa Cruz, CA); Albertus Strasheim (San Francisco, CA)
Assignee: CLOUDFLARE, INC.
H04L63/0435G06F21/335H04L9/0825H04L9/0841H04L9/0869H04L9/3263H04L63/0442H04L63/061H04L63/0823H04L63/0869H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,791,099
App. No.
16/159,437
Granted
Sep 29, 2020
Kind
B2
Abstract

A first server receives a set of cryptographic parameters from a second server. The set of cryptographic parameters is received from the second server as part of a secure session establishment between a client device and the second server. The first server accesses a private key that is not stored on the second server. The first server signs the set of cryptographic parameters using the private key. The first server transmits the signed set of cryptographic parameters to the second server. The first server receives, from the second server, a request to generate a premaster secret using a value generated by the second server that is included in the request and generates the premaster secret. The first server transmits the premaster secret to the second server for use in the secure session establishment between the client device and the second server.

Claims (56)

1. A method in a first server, comprising the first server performing the following:

receiving a set of cryptographic parameters from a second server, wherein the set of cryptographic parameters is received from the second server as part of a secure session establishment between a client device and the second server;

accessing a private key, wherein the private key is not stored on the second server;

signing the set of cryptographic parameters using the private key;

transmitting the signed set of cryptographic parameters to the second server;

receiving, from the second server, a request to generate a premaster secret using a value generated by the second server that is included in the request;

generating the premaster secret using the value generated by the second server that is included in the request; and

transmitting the premaster secret to the second server for use in the secure session establishment between the client device and the second server.

2. The method of claim 1 , further comprising the first server performing the following:

prior to transmitting the set of cryptographic parameters to the second server, participating in a secure session establishment procedure that establishes a secure session between the first server and the second server, wherein transmitting the set of cryptographic parameters to the second server is over secure session.

3. The method of claim 2 , wherein as part of participating in the establishment of the secure session, the first server performs the following:

requesting a certificate from the second server;

receiving the certificate from the second server; and

using the received certificate to authenticate the second server.

4. The method of claim 1 , further comprising the first server receiving, from the second server, an indication of a domain in which the client device is attempting to connect via the secure session, and wherein the accessed private key corresponds to a public key associated with the indicated domain.

5. The method of claim 1 , wherein prior to transmitting the set of cryptographic parameters to the second server, the first server verifying that the second server is communicating with the first server with an IP address having a value expected by the first server.

6. The method of claim 1 , wherein the secure session establishment between the client device and the second server uses a Diffie-Hellman key exchange mechanism.

7. An apparatus, comprising:

a first server to include a set of one or more processors and a set of one or more non-transitory computer-readable storage mediums that is to store instructions, that when executed by the set of processors, cause the set of processors to perform the following operations:

receive a set of cryptographic parameters from a second server, wherein the set of cryptographic parameters is to be received from the second server as part of a secure session establishment between a client device and the second server;

access a private key, wherein the private key is not stored on the second server;

sign the set of cryptographic parameters using the private key;

transmit the signed set of cryptographic parameters to the second server;

receive, from the second server, a request to generate a premaster secret using a value generated by the second server that is included in the request;

generate the premaster secret using the value generated by the second server that is included in the request; and

transmit the premaster secret to the second server for use in the secure session establishment between the client device and the second server.

8. The apparatus of claim 7 , wherein the set of one or more non-transitory computer-readable storage mediums further is to store instructions, that when executed by the set of processors, cause the set of processors to perform the following operations:

prior to transmission of the set of cryptographic parameters to the second server, participate in a secure session establishment procedure that establishes a secure session between the first server and the second server, wherein transmission of the set of cryptographic parameters to the second server is over secure session.

9. The apparatus of claim 8 , wherein as part of participation in the establishment of the secure session, the first server is to perform the following:

request a certificate from the second server;

receive the certificate from the second server; and

use the received certificate to authenticate the second server.

10. The apparatus of claim 7 , wherein the set of one or more non-transitory computer-readable storage mediums further is to store instructions, that when executed by the set of processors, cause the set of processors to perform the following operations:

receive, from the second server, an indication of a domain in which the client device is attempting to connect via the secure session, and wherein the accessed private key is to correspond to a public key associated with the indicated domain.

11. The apparatus of claim 7 , wherein the set of one or more non-transitory computer-readable storage mediums further is to store instructions, that when executed by the set of processors, cause the set of processors to perform the following operation:

prior to transmission of the set of cryptographic parameters to the second server, verify that the second server is communicating with the first server with an IP address having a value expected by the first server.

12. The apparatus of claim 7 , wherein the secure session establishment between the client device and the second server is to use a Diffie-Hellman key exchange mechanism.

13. A non-transitory machine-readable storage medium that provides instructions that, when executed by a processor of a first server, causes said processor to perform operations comprising:

receiving a set of cryptographic parameters from a second server, wherein the set of cryptographic parameters is received from the second server as part of a secure session establishment between a client device and the second server;

accessing a private key, wherein the private key is not stored on the second server;

signing the set of cryptographic parameters using the private key;

transmitting the signed set of cryptographic parameters to the second server;

receiving, from the second server, a request to generate a premaster secret using a value generated by the second server that is included in the request;

generating the premaster secret using the value generated by the second server that is included in the request; and

transmitting the premaster secret to the second server for use in the secure session establishment between the client device and the second server.

14. The non-transitory machine-readable storage medium of claim 13 further providing instructions that, when executed by the processor, causes the processor to perform the following:

prior to transmitting the set of cryptographic parameters to the second server, participating in a secure session establishment procedure that establishes a secure session between the first server and the second server, wherein transmitting the set of cryptographic parameters to the second server is over secure session.

15. The non-transitory machine-readable storage medium of claim 14 , wherein as part of participating in the establishment of the secure session, the first server performs the following:

requesting a certificate from the second server;

receiving the certificate from the second server; and

using the received certificate to authenticate the second server.

16. The non-transitory machine-readable storage medium of claim 13 further providing instructions that, when executed by the processor, causes the processor to perform the following:

receiving, from the second server, an indication of a domain in which the client device is attempting to connect via the secure session, and wherein the accessed private key corresponds to a public key associated with the indicated domain.

17. The non-transitory machine-readable storage medium of claim 13 further providing instructions that, when executed by the processor, causes the processor to perform the following:

prior to transmitting the set of cryptographic parameters to the second server, the first server verifying that the second server is communicating with the first server with an IP address having a value expected by the first server.

18. The non-transitory machine-readable storage medium of claim 13 , wherein the secure session establishment between the client device and the second server uses a Diffie-Hellman key exchange mechanism.

Assignments (2)
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2018
From: PAHL, SÉBASTIEN ANDREAS HENRY; TOURNE, MATTHIEU PHILIPPE FRANÇOIS; SIKORA, PIOTR; BEJJANI, RAY RAYMOND; KNECHT, DANE ORION; PRINCE, MATTHEW BROWNING; GRAHAM-CUMMING, JOHN; HOLLOWAY, LEE HAHN; STRASHEIM, ALBERTUS
To: CLOUDFLARE, INC.
Reel/Frame 047311/0705 →
Continuity (4)
Division 15413187 · Jan 23, 2017
Continuation 14315241 · Jun 25, 2014
Continuation 13788784 · Mar 7, 2013
Related Publication 20190044924A1 · Feb 7, 2019